Audit History
terraform-module-library - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 8, 2026, 11:33 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 8, 2026, 11:33 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 1, 2026, 12:53 AM | No confirmed findings | 2 | No capability change |
| v5 | Jul 1, 2026, 12:53 AM | No confirmed findings | 2 | No capability change |
| v4 | Jan 17, 2026, 08:24 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:24 AM | No confirmed findings | 0 | Contains scriptsNetwork accessFilesystem accessExternal commands |
| v2 | Jan 4, 2026, 04:33 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:33 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 11:33 AM
The detected items are false positives from Markdown fences, Terraform examples, private CIDR examples, relative module paths, and Terraform resource attribute names. I found no prompt injection, exfiltration intent, command execution, or unsafe file access in the reviewed files.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (20)
🌐 Network access (4)
📁 Filesystem access (3)
Jul 8, 2026, 11:33 AM
The detected items are false positives from Markdown fences, Terraform examples, private CIDR examples, relative module paths, and Terraform resource attribute names. I found no prompt injection, exfiltration intent, command execution, or unsafe file access in the reviewed files.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (20)
🌐 Network access (4)
📁 Filesystem access (3)
Jul 1, 2026, 12:53 AM
Static analysis reported many high-risk patterns, but review found they are Markdown examples, Terraform snippets, private CIDR examples, or ordinary documentation text rather than executable malware. The remaining risk is operational: copied Terraform and Terratest examples can create or destroy real cloud resources if run without review.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (8)
🌐 Network access (4)
📁 Filesystem access (3)
Detected Patterns
Jul 1, 2026, 12:53 AM
Static analysis reported many high-risk patterns, but review found they are Markdown examples, Terraform snippets, private CIDR examples, or ordinary documentation text rather than executable malware. The remaining risk is operational: copied Terraform and Terratest examples can create or destroy real cloud resources if run without review.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (8)
🌐 Network access (4)
📁 Filesystem access (3)
Detected Patterns
Jan 17, 2026, 08:24 AM
Documentation-only skill containing markdown files with Terraform patterns and examples. No executable code (.tf, .go, .sh files present). Static findings are all false positives triggered by documentation text patterns (Terraform resource names, module paths, example CIDR blocks). Content matches stated purpose of providing IaC guidance.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (1)
📁 Filesystem access (1)
⚙️ External commands (1)
Jan 17, 2026, 08:24 AM
Documentation-only skill containing markdown files with Terraform patterns and examples. No executable code (.tf, .go, .sh files present). Static findings are all false positives triggered by documentation text patterns (Terraform resource names, module paths, example CIDR blocks). Content matches stated purpose of providing IaC guidance.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (1)
📁 Filesystem access (1)
⚙️ External commands (1)
Jan 4, 2026, 04:33 PM
Pure documentation skill containing only markdown files with Terraform patterns and examples. No network calls, no file system access, no code execution. Content matches stated purpose of providing IaC guidance.
Jan 4, 2026, 04:33 PM
Pure documentation skill containing only markdown files with Terraform patterns and examples. No network calls, no file system access, no code execution. Content matches stated purpose of providing IaC guidance.